Skip to content

Security & GDPR

UK-built. UK-hosted.Audited underneath.

Exactly how 99 Data Rooms keeps your documents safe: where they live, who can reach them, the controls you hold, and the audited platforms it all runs on. No hand-waving.

Hosting
London, UK
At rest
AES-256
In transit
TLS 1.2+
Data residency
UK primary, EU backups

Built on audited infrastructure

Certified where it counts.

We don't run our own data centres. 99 Data Rooms runs on platforms that are independently audited to the standards enterprise security teams ask for, in a UK region.

SupabaseData layer
SOC 2 Type IIISO 27001

Database, storage, authentication and edge functions. Your documents and their data live here, in the London region.

CloudflareWebsite edge & firewall
SOC 2 Type IIISO 27001:2022ISO 27018ISO 27701PCI DSS L1

Website delivery and DNS, with a web application firewall and DDoS protection in front of every request to the site.

Backups & recoveryResilience
AutomatedEncryptedEU region

Your primary data lives in the UK (London). Backups are made automatically and encrypted at rest in an EU region, so nothing is lost if something breaks.

The SOC 2 and ISO certifications above are held by Supabase and Cloudflare, our infrastructure providers. 99 Data Rooms runs on their audited platforms and does not claim to have completed those audits itself. Primary data is resident in the UK (London); encrypted backups are held in an EU region. A Data Processing Agreement is available on request.

Our own controls

What we do on top.

01

Encryption everywhere

TLS 1.2+ in transit. AES-256 at rest for every stored document, handled by the platform.

02

Row-level security

Every database query is scoped to your identity in Postgres. No cross-tenant leaks by construction.

03

Short-lived signed URLs

Storage is never public. Access is granted through signed URLs that expire in minutes, re-issued per view.

04

Controls on every link

Email gate, one-time-code verification, NDA acceptance, expiry, max views and one-click revocation.

05

Hardened edge

Isolated edge runtime for server logic. Every public endpoint validates its own credential server-side on each request and is rate limited.

06

Audit trail

A page-by-page visit log per share link, retained 24 months, visible in your own analytics. Signed documents carry their own audit page: every field value captured, with a per-field timestamp, signer IP and intent-to-sign consent.

AI assistants

What we bound, and what we cannot prevent.

A document in a data room can contain text written to be read by an AI assistant rather than by a person. If a member connects an assistant, it may act on that text. This is inherent to letting an assistant read documents at all, and we do not claim to prevent it. Nobody can. What we can do is bound what a compromised assistant is able to reach, so the blast radius is a permissions question rather than a trust question.

01

It is only ever one member

An assistant acts as the member who connected it and can never exceed that member's own permissions. That is enforced in the database, on the path every tool call goes through, not in the agent and not in the application.

02

Scope only narrows

A human picks which rooms an assistant may see, on a consent screen, with two-factor authentication. That choice can only ever narrow what the database would already allow. It can never widen it.

03

Nothing is silently overwritten

Document writes are compare-and-swap against the version being edited. An instruction smuggled into a document cannot quietly overwrite a version somebody else is working on: a stale write is refused, and the refusal names the current version.

04

The owner holds a switch and a log

AI access is off when a room is created and stays off until its owner turns it on. Turning it back off takes effect immediately, including for assistants already connected. Owners can read the log of automated access to their own rooms.

Responsible disclosure

Found a vulnerability?

Email datarooms@99developer.com with reproduction steps. We acknowledge within one business day and remediate critical issues within seven days. No bounty yet, but we will credit you.

Compliance, plainly

  • UK GDPR and Data Protection Act 2018 aligned
  • Runs on SOC 2 Type II and ISO 27001 platforms (Supabase and Cloudflare)
  • Primary data stored in the UK (London), encrypted backups in an EU region; DPA on request
  • Full data export and account deletion within 30 days
  • No third-party trackers running on your viewers

DPA available on request, see /legal/dpa.

“Security on a document-sharing product is a hygiene bar, not a marketing one. We publish what we actually do, name the platforms we stand on, and sign a DPA on request.”
A note from the founder  99 Developers